Re: A Quickhack

Raymond S Brand <[email protected]> Sun, 26 Oct 2003 15:28:55 -0500
Newsgroups gmane.ietf.asrg.rmx
Message-ID <[email protected]>
Hadmut Danisch wrote:
> 
> On Sun, Oct 26, 2003 at 08:11:14AM -0500, Richard Rognlie wrote:
> >
> > It might tell you that "yes, this host is allowed to be this IP"
> > but it says nothing about "this IP is allowed to send mail and
> > claim to be this hostname"
> >
> 
> OK, I've thought a little bit about it. We need to discuss it.
> 
> - As long as we need to verify the HELO hostname only to keep
>   relaying running that would be broken by MAIL FROM checking
>   otherwise, we don't need it, because the A record does the job
>   in my eyes.

Others disagree. Not all MTA operators will do the MAIL FROM checking
anytime soon due to the collateral damage it causes (aliases and
.forwards).

> - If you want to cover more functionality, i. e. giving the domain
>   admin the opportunity to disallow certain machines to deliver
>   e-mail, then we'd have DRIP (or apply our combined mechanism to
>   the HELO command).

OK, so far.

>   Where's the advantage over the A record?

Not all machines with a A RR are authorized by the domain owner to
send/relay mail. How do you distinguish?

>   If in a company or university has computers out of control
>   which could be used by abusive employees, hijacked or virus
>   infected, it could prevent abusive delivery (if they do not have
>   a firewall, which does it anyway).

Or ISPs with customers?

> 
> Well, we can do this. But I think we should discuss and decide,
> whether we also want to cover this functionality. Until now I was
> under the impression that we verify HELO only as a fallback to keep
> forwarding alive.

That view assumes DRIP does not provide useful information unrelated
to the MAIL FROM checks proposed. Not all MTAs will be willing to
perform the MAIL FROM checks due to the collateral damage.

> If we support it, we should at least have a precise statement why
> we do it.

We should have a precise statement why we support something for each
thing we support.


Raymond S Brand